CVE-2015-6476: Critical severity advantech eki-1321 series firmware vulnerability
Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6476?
CVE-2015-6476 is considered a high severity vulnerability due to the presence of hardcoded SSH keys in the affected devices.
How do I fix CVE-2015-6476?
To mitigate CVE-2015-6476, upgrade the firmware of affected Advantech devices to the latest version beyond the vulnerable releases.
Which devices are affected by CVE-2015-6476?
CVE-2015-6476 affects Advantech EKI-122x-BE devices with firmware before version 1.65, EKI-132x devices before version 1.98, and EKI-136x devices before version 1.27.
What are the risks associated with CVE-2015-6476?
The risks of CVE-2015-6476 include unauthorized remote access to devices due to exploitable hardcoded SSH keys.
Is it safe to use affected Advantech devices without fixing CVE-2015-6476?
Using affected Advantech devices without addressing CVE-2015-6476 exposes the devices to significant security risks.